1. Who we are and who is accountable
The online shop at feelit.ca is operated by 2828468 ALBERTA INC., a corporation incorporated in Alberta, Canada, carrying on business as FeelIt, at 3-1626 28 Ave SW, Calgary, AB T2T 1J4. That corporation is the organization accountable for the personal information under our control.
Privacy Officer. The person in charge of protecting personal information at 2828468 ALBERTA INC. is the Director of the corporation, whom this policy calls the Privacy Officer. You can reach that person by email at [email protected] — please put “Privacy” in the subject line — or by mail at 2828468 ALBERTA INC., 3-1626 28 Ave SW, Calgary, AB T2T 1J4. If you want the name of the individual who holds that role, ask us and we will tell you. The same person answers questions about how our service providers outside Canada collect, use, disclose or store your personal information. Ask us and we will send you our written information about those companies — by email or by post, whichever you prefer. Sections 6 and 7 explain who they are and where they are.
FEELIT™ is a trademark of 2828468 ALBERTA INC.
2. Which laws apply
We are an Alberta corporation, so Alberta’s Personal Information Protection Act (PIPA) governs the personal information we handle within Alberta, and Canada’s federal Personal Information Protection and Electronic Documents Act (PIPEDA) governs it whenever it crosses a provincial or national border. That happens for every customer, because our servers and some of our service providers are outside Canada. Where the two differ, we apply the stricter one. If you are in Quebec or another province with its own private-sector privacy law, that law applies to you in addition — see section 14.
3. What we collect
If you buy
- Your name, email address and phone number, and the province and postal code you enter at checkout. We use the province and postal code to check that we sell where you are — FeelIt currently sells and honours certificates only outside Quebec — and we keep them with the order. If a purchase is declined because of the province, we record only the province and the first character of the postal code, as a site statistic without your name; never the full postal code.
- What you bought. For a booking: the experience, the date and time, and how many people. For a gift certificate: the experience it suggests or the amount you chose, how many people, the recipient’s name and email address, and any gift message you write.
- Your acceptance of the participant release — see The participant release below.
- Payment is handled by Stripe on its own secure pages — we never see or store your card number. Stripe tells us that the payment succeeded and gives us a reference for it.
- Anything you write to us. Email you send us is kept as a conversation thread under your email address — the message, the formatted copy of it, and the name, size and type of any attachment, but not the attached file itself — so we can see what was asked and what was answered.
If someone sends you a gift
- The buyer gives us your name and email address so we can send you the certificate. We use them to deliver it and to support the experience it is for — never for marketing, and we never add you to a mailing list.
- You are our customer in your own right. A person who receives a gift certificate is a consumer under Alberta’s Consumer Protection Act, and the rights in section 12 — and in our Terms of Service and Refund Policy — are yours.
- What the buyer can see about you. The buyer sees the name and email address they entered, whether the certificate has been sent, activated and used, and the remaining value on it. The buyer does not see the details you enter when you activate it, the experience or the date you choose, or who attends.
- You did not ask us for any of this, and we know it. If you would rather we did not hold your details, tell us: we will take your name and email off the certificate, stop writing to you about it, and delete what we are not required by law to keep — see section 12.
When a certificate is activated or a date is chosen
- The person activating a certificate gives a name, an email address, a phone number and a province, and accepts the participant release. We use them to run the certificate and to reach that person about the date. Where the province is Quebec, the activation does not go through.
- When a date is chosen, we record the experience, how many people, the date and time, the value applied from the certificate, any difference paid by card (through Stripe, as above) and the operator we assigned. The operator receives only the attendee’s first name and the number of people — section 6 sets out exactly what it receives.
- The code on the certificate is what authorises this: whoever holds it can see the remaining value, activate the certificate and choose a date without signing in. Looking up a code shows no email address. That is why we limit how many codes can be tried from one address, and why the code should be kept confidential.
- If a date is moved or cancelled, we keep a record of it: the time it was moved from, the time it was moved to, who did it, and the reason if one is given. Within 48 hours of the start, a change goes through us — write to us and we decide — and what that adds to your record is your message and the outcome.
The participant release
- Before paying — for a booking or for a certificate — and before activating a certificate, the person doing so accepts the FeelIt Participant Release. We record the version and a fingerprint (hash) of the text accepted; the time each of its acknowledgements was ticked; the name, email address and province given; the experience and number of people it was accepted for, where those were chosen; the IP address it came from; the identifying string your browser sends with each request, which names the browser, its version and the operating system; and the time. When a date is confirmed or moved, the acknowledgement of the operator named for that date is recorded the same way.
- This exists so that what was accepted, and when, can be proved later. We keep it for 11 years (section 9). A release accepted but never followed by a purchase or an activation is deleted after 24 hours.
If you conduct experiences for us
- Business and contact details, the experiences you publish, and the documents you upload with their expiry dates — the evidence that FeelIt is an additional insured on your liability policy (an endorsement, a policy page or a certificate, and your broker’s letter where one is needed), your workers’ compensation clearance, and the licences the activity needs.
- What we need to prepare your monthly statements and to keep tax records: your legal name and address, your GST/HST number if you have one, and the details you give us for payment.
- A record of your acceptance of our operator supply agreement: the version accepted, the date and time, the IP address it came from, the identifying string your browser sends (browser, version and operating system), and the signature you type or draw. This exists so that what was agreed, and when, can be proved later.
- The assignments we send you — the experience, the date and time, how many people and the attendee’s first name — and what you record against them: completed, no-show, or declined with your reason.
- Messages you send us from the Support page in your dashboard, and any files you attach to them, are kept as one continuous thread for your account, together with our replies. The files stay on our own server.
If you sell for us
- If we invite you to sell for us, we create an account for you — your name and email address — before you have agreed to anything, so that your personal onboarding link works. If you never take it up, tell us and we will delete it.
- Your name and contact details, the operators you introduced, and the assignments credited to you.
- A record of your acceptance of our sales agreement: the version, the share of gross margin it carried, the date and time, the IP address, the identifying string your browser sends (browser, version and operating system) and the signature you type or draw. The yearly statement that you work independently is signed and stored the same way.
- A record of what we have paid you: the amount, the period, the date and the method.
- Messages you send us from the Support page in your dashboard, and any files you attach to them, are kept as one continuous thread for your account, together with our replies. The files stay on our own server.
Everyone who visits the site
- Our servers see the ordinary technical details of a request, including your IP address. We use them to keep the site running and to stop abuse — for example, we limit how many certificate codes can be tried from one address in ten minutes.
- When the site is limited to invited visitors, as it has been at times, entering the access code we gave you adds the address you are connecting from to a list of allowed addresses. That list stays until we clear it — see section 9.
- The photos on our pages are delivered by Cloudinary, so your browser fetches them from Cloudinary directly and Cloudinary sees that request, including your IP address — the same thing that happens on any site whose images come from another company. Sections 6 and 7 say who Cloudinary is and where those companies are.
- First-party analytics, if you leave them on. Section 8 lists exactly what is stored and how to switch it off.
4. Why we use it
- To take orders, issue certificates, activate and redeem them, fix and move dates, and provide support.
- To assign an operator to your date and give it what it needs to conduct the experience: the experience, the date and time, how many people, and the attendee’s first name.
- To check that we sell where you are (section 3).
- To record the participant release, so that what was accepted can be proved.
- To send transactional email: receipts, certificates, date confirmations and changes, and answers to what you ask us.
- To prevent fraud and abuse of certificate codes.
- To keep the tax and accounting records the law requires us to keep.
- Marketing email. We do not send any today. If we start, it will be opt-in only — you would have to ask for it separately — and every message will carry a working unsubscribe link, as Canada’s anti-spam law requires. We do not send marketing to gift recipients.
- Business invitations. We invite businesses to conduct experiences for us. We write to a business address only where we may lawfully do so — typically an address the business publishes for enquiries of this kind, or one it gave us directly — and we record why we wrote and where the address came from. Every invitation we send to a business identifies us, gives our mailing address and carries a one-click unsubscribe that needs no account: use it and we will not write again. Some of these invitations are sent by representatives working for us. Their messages identify us as well, and an unsubscribe reaches us the same way — through our own system it takes effect at once, and in every case within ten business days, which is what our agreement with them requires. Inviting someone to represent us is a different thing: that is a message written to one person, and telling us you are not interested ends it. None of this applies to customers or gift recipients.
5. Consent, and how to withdraw it
- We ask for what we need to do the thing you asked for, and we say why at the point we ask.
- Analytics work on an opt-out basis: they are on by default, the banner is the notice, and switching them off takes effect immediately (section 8). An analytics event is stored with no account, no name, no email address and no IP address attached; section 8 lists exactly what an event does carry.
- You can withdraw your consent at any time by writing to us. Some things then stop working: we cannot deliver a certificate without an email address, and we cannot assign your date to an operator without giving it a first name and the number of people.
- Withdrawing consent does not reach records we are required by law to keep — see section 9.
- If we ever want to use information we already hold for a new purpose, we will ask you first. We will not do it by quietly updating this page.
6. Who we share it with
- The operator assigned to your date receives the experience, the date and time, how many people, and the first name of the person attending — and nothing else. It does not receive your email address, your phone number, the buyer’s details, the gift message, or what was paid. It is told when the date is fixed: for a booking, when you pay; for a certificate, when the holder confirms a date — buying a certificate tells no operator anything. If we assign a different operator, the first one is told the assignment is cancelled and the new one receives the same four things. Our agreement with operators forbids using any of it for their own marketing.
- Sales representatives who introduced an operator see the margin figure on the assignments that operator performs — never a customer’s name, email address or order.
- Service providers that run our infrastructure, each of which we use for one purpose only:
- Stripe — payments and refunds (United States).
- Resend — sending our email and receiving mail sent to us (United States).
- Cloudinary — storing and delivering the photos on our pages. Your browser loads those photos from Cloudinary itself, so Cloudinary sees the request, including your IP address.
- The company that runs our servers — the machines our site and database run on (European Union).
- Authorities, where the law requires it.
- We do not sell personal information. Ever.
7. Where your information is stored
Our servers are in the European Union. Stripe and Resend process data in the United States. Cloudinary delivers our images on its own content-delivery network, which has locations in several countries. If you want to know the exact country a particular company stores or serves your information from, ask us in writing: we will put the question to that company and tell you what we are told.
We also keep a copy of our database in Canada, on equipment we control in Calgary. That copy is refreshed twice a day.
This means your information may be stored and processed outside Canada, and while it is there it may be accessible to the authorities of those countries under their own laws. Using a company outside Canada does not reduce our responsibility for your information: we remain accountable for it wherever it is handled.
You can ask us for information about our policies and practices in respect of service providers outside Canada, and we will send it to you in writing — by email or by post, whichever you prefer. The Privacy Officer described in section 1 is the person who answers questions about how those companies collect, use, disclose or store your personal information.
8. Cookies, browser storage and analytics
What we store on your device
- feelit_tokens — keeps you signed in. Browser storage, written when you sign in.
- feelit_cart — what is in your cart. Browser storage. It is created when the site first loads in your browser, is empty until you add something, and is updated as you add or remove items.
- feelit_theme — your light or dark choice. Browser storage, written when you choose a theme.
- feelit_cookie_prefs — your cookie choices. This one is stored twice: as a real cookie, which your browser sends to us with every request to feelit.ca, and as a copy in browser storage. The cookie is set to expire two years after your most recent visit and is refreshed every time you come back; the copy in browser storage stays until you clear it. Each copy restores the other, so clearing both is what brings the banner back.
The Analytics switch in the banner is the one that changes what we collect. The other three are how the site works in your browser: your sign-in token is sent to us when your browser asks us for something on your account, feelit_cookie_prefs travels with every request because that is what a cookie does, and your cart and your theme stay on your device. None of them is used to follow you across other websites.
Analytics
- First-party only. There are no third-party advertising or social trackers on this site — not one. The analytics data goes to us and to nobody else.
- Analytics are on by default. The consent banner appears on your first visit: open Manage Cookies, switch Analytics off and save. It takes effect immediately, without reloading the page. After that the banner does not come back, and the way in is the Cookie preferences link in our footer — at the bottom of this page, of the home page and of every experience page. A few screens, such as the checkout and the certificate page, have no footer; open one that does. Your choice is stored on your device, so we cannot change it for you: change it there, or clear both copies of feelit_cookie_prefs as described above to bring the banner back.
- We record five things: opening a page, opening an experience, adding something to the cart, starting checkout, and a confirmed purchase.
- Stored with each event: the type of event, the address of the page it happened on, the experience it relates to when there is one, small details such as whether a cart item was a gift and how many people, and the time. No account, no name, no email address and no IP address is attached to an analytics event — not even when you are signed in.
9. How long we keep it
- Orders, bookings and certificates: for as long as the certificate can still be used, and after that as part of the tax and accounting records we keep of our sales. A certificate does not expire, so we hold the order and the certificate record until its remaining value has been used, however long that takes.
- Participant release records (section 3): 11 years from the day the release was accepted, so that what was accepted can be proved for as long as a claim about the experience could still be brought. A release accepted but never linked to a purchase or an activation is deleted after 24 hours.
- Account data: while your account exists.
- Messages you send us: kept as a conversation thread under the email address they came from — and, for messages sent from the Support page in an operator’s or sales representative’s dashboard, with the files attached to them — for as long as we may need them to deal with what was asked and with anything that follows from it.
- Operator and sales representative records: the agreement and the record of its acceptance (the version, the date and time, the IP address, the identifying string your browser sends, and the signature), the monthly statements, what we have paid you, and documents you upload such as insurance evidence — kept while the agreement is in force, and after that for as long as a claim about it could still be brought and as part of our tax and accounting records.
- Analytics events: kept as site statistics for as long as those statistics are useful to us. They are not attached to an account, a name, an email address or an IP address.
- Server records of requests, including IP addresses: kept on the server only for as long as we need them to run the site, investigate faults and stop abuse. We do not build a profile of you from them.
- Addresses allowed past our access wall: kept until we clear the list.
- Records of security incidents: at least two years — see section 11.
- You can ask us to delete anything we are not required to keep — see section 12.
10. How we protect it
- Traffic between you and the site is encrypted (HTTPS).
- Card details never reach our servers: Stripe’s own payment page handles them.
- The sign-in links we email can only be used to sign in to a customer account, they stop working after seven days, and changing your password invalidates any link already sent.
- Administrative access to our server needs a key rather than a password, and repeated failed attempts are blocked automatically. Both our own administration and our automated deployment reach the server only over a private network channel, using key-only access.
- The database is backed up every night on the server and copied to equipment we control in Canada twice a day, and we test a restore every week.
No system is perfect. Section 11 says what we do when something goes wrong.
11. If there is a breach
If a breach of our security safeguards creates a real risk of significant harm to you, we will report it to the privacy regulators and tell you. Federal law (PIPEDA) requires both. Alberta’s PIPA requires the report to the Alberta Commissioner without unreasonable delay. We will tell you as well. If you are in Quebec, Quebec’s law applies too: where an incident presents a risk of serious injury we would notify the Commission d’accès à l’information and each person affected.
We keep a register of confidentiality and security incidents whether or not an incident has to be reported, and we keep those records for at least two years.
12. Your rights
- Ask what personal information we hold about you, and get a copy of it.
- Ask us to correct it if it is wrong.
- Withdraw your consent, with the consequences described in section 5.
- Ask us to delete information we are not legally required to keep.
- Complain to the Privacy Officer (section 1) at [email protected]. You can also take a complaint to the Office of the Information and Privacy Commissioner of Alberta or to the Privacy Commissioner of Canada. If you are in Quebec, you can go to the Commission d’accès à l’information.
There is no self-service button for any of this yet: write to us at [email protected] or by mail to the address in section 1, and we will handle it.
If you are a gift recipient, these rights are yours too — including asking us to delete your details if you do not want the gift. Tell us and we will take your name and email off the certificate and stop writing to you about it.
13. Children
Purchases on FeelIt are for adults (18+), and only an adult accepts the participant release online. Where an experience admits participants under 18, the operator’s own parental consent process applies on site; we do not collect a child’s details ourselves.
14. Quebec and other provinces
FeelIt currently sells and honours certificates only outside Quebec. If you are in Quebec, or in another province with its own private-sector privacy law, and you visit the site or write to us, additional rights may apply to you under that law. Contact us and we will honour them. Section 1 publishes the title and contact details of the person in charge of protecting personal information; section 11 names the Quebec regulator.
15. Changes to this policy
We may update this policy. The date and version at the top tell you which text you are reading and when it was posted. If a change is material, it takes effect no earlier than 30 days after we post it here. We keep previous versions — ask us for the one that applied to you. As section 5 says, a new use of information we already hold needs your consent: an updated page is not a substitute for asking you.
16. Contact
Director of the corporation (Privacy Officer), 2828468 ALBERTA INC., 3-1626 28 Ave SW, Calgary, AB T2T 1J4 — [email protected]. See also our Terms of Service and Refund Policy.